Legal

Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Imapost ("we", "us") collects, uses, and safeguards personal data when you use our AI Marketing Operating System.

Data we collect

  • Account data: name, email, avatar, workspace membership.
  • Content data: posts, media, campaigns, brand kits, and AI generations you create in your workspace.
  • Social connections: encrypted OAuth tokens for platforms you connect.
  • Usage data: product analytics, error logs, IP address, device and browser metadata.
  • Billing data: handled by Stripe / Razorpay; we store only invoice metadata, never raw card details.

How we use it

To operate the service, generate content on your behalf, publish to connected platforms, provide analytics, prevent abuse, and comply with legal obligations.

AI processing

Prompts and content you submit may be processed by our AI providers (OpenAI, Google Gemini, Anthropic Claude) under their data-processing terms. We do not use your content to train foundation models.

Sharing

Only with sub-processors required to run the service (Supabase, Vercel, Stripe, Razorpay, AI providers, connected social platforms) and when required by law.

Retention

Workspace data is retained while your account is active. On deletion, personal data is removed within 30 days except where required for legal, accounting or fraud-prevention purposes.

Your rights

Access, export, correct, or delete your data from workspace settings, or by emailing privacy@imapost.com. EU/UK residents have rights under GDPR; California residents have rights under CCPA/CPRA.

Security

TLS in transit, encryption at rest, per-workspace RLS isolation, AES-256-GCM for social tokens. Access is scoped by role and audited.

Contact

Data Protection Officer — dpo@imapost.com.